The Procolored Printer Software Malware
Updated 5 Oct 2026 · Incident date 1 Oct 2024 · vendor binary
Procolored driver/software bundles for F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro, hosted on the vendor's official download linksProcolored driver and utility executables in the downlo...Software for six Procolored printer lines carried malware. The affected lines are the F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro. The last infected update dated from October 2024, and Procolored removed the downloads on 8 May 2025.
The malware included the XRed backdoor and a file infector and clipboard thief named SnipVex.
What happened
A YouTuber, Cameron Coward, found malware on a USB stick that came with a UV printer from Procolored. CyberInsider reports that G Data analyst Karsten Hahn then confirmed infections in the vendor's downloadable software, about 8 GB in total.
G Data found 39 detections across 20 files with unique hashes. The infected PrintExp.exe held both payloads, which suggests the developer or build systems were compromised, according to Security Online.
The malware had three parts:
- XRed backdoor. A Delphi backdoor, active since at least 2019. It runs commands, takes screenshots, logs keystrokes and handles files.
- SnipVex. A previously undocumented file infector. It adds code to the front of
.exefiles and watches drives so it can spread. - A clipboard thief. A .NET program that swaps copied Bitcoin addresses for the attacker's address. The attacker's wallet received about 9.3 BTC, and activity stopped in March 2024.
Procolored said that software moved by USB might have introduced the malware. It promised to scan all files before it uploaded them again. G Data and others advised reinstalling the operating system on affected machines.
Affected versions
The affected items are the driver and software bundles for six printer models. The sources give no version numbers.
- Procolored F8
- Procolored F13
- Procolored F13 Pro
- Procolored V6
- Procolored V11 Pro
- Procolored VF13 Pro
CyberInsider reports that the last infected update was in October 2024 and that downloads came down on 8 May 2025. Any bundle you downloaded or copied from the USB stick before then needs a check.
Indicators of compromise
- Executables in Procolored software, such as
PrintExp.exe, with antivirus detections namedWin32.Backdoor.XRedRAT.AorMSIL.Trojan-Stealer.CoinStealer.H - SnipVex infection marker bytes
0x0A 0x0B 0x0Cin infected files - Bitcoin address of the attacker wallet:
1BQZKqdp2CV3QV5nUEsqSg1ygegLmqRygj
The Bitcoin address and marker come from the Hacker News report on this malware family. I could not confirm file hashes beyond the counts above.
How to check
Scan the printer software folder and any copied installers with your antivirus tool, and check for the detection names above. Then check for the file that G Data named.
Get-ChildItem -Path C:\ -Recurse -Filter PrintExp.exe -ErrorAction SilentlyContinue | Get-FileHash -Algorithm SHA256
Submit the hash to a malware scanning service to see whether it is flagged. Also check your antivirus exclusion list for entries you did not add. G Data advises doing this, because the vendor told users to exclude the files.
What to do now
- Disconnect any machine that ran Procolored software from before May 2025.
- Remove antivirus exclusions you did not set.
- Back up documents only, then reformat the machine and reinstall the operating system.
- Change passwords and keys that were used on that machine.
- Check wallets and payment addresses. The clipboard thief changed copied addresses.
- Do not dismiss antivirus alerts on vendor software as false positives.
Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See all attacks.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 16 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED Procolored.exe It now downloads from the internet. It did not before.
Frequently asked questions
Which Procolored printers had infected software?
The F8, F13, F13 Pro, V6, V11 Pro and VF13 Pro. The last infected update was in October 2024.
What malware was in the Procolored software?
G Data found the XRed backdoor, a clipboard thief that swaps Bitcoin addresses, and a file infector called SnipVex.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.